Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
In this campaign we observed a PowerShell script being downloaded that installs a malicious Chromium-based browser extension that targets Google Chrome, Brave and Opera.
The command used for extraction is as follows: "C:\Users\???\AppData\Roaming\Viqwo Stars Ci\Rotq App\UnRar.exe" x -p3809610121t -o+ ...
ErrTraffic begins after someone reaches a compromised WordPress website. The injected JavaScript does not contain the final destination in clear text.
This includes resolving LdrLoadDll, which loads bcrypt.dll while bypassing the more commonly hooked LoadLibrary call.
The sample requires user interaction to execute, triggered by the execution of the setup.msi file.
The main purpose of the malware that is dropped by the Satacom downloader is to steal BTC from the victim’s account by performing web injections into targeted cryptocurrency websites. The malware attempts to do this by installing an extension for Chromium-based web browsers.
Finally, the PS script recursively searches for any link (.LNK) file in the above locations and modifies the “Target” parameter for all existing browser shortcuts with the flag “–load-extension=[pathOfExtension]” so that the shortcut will load the browser with the malicious extension installed.
The shellcode then proceed to start explorer.exe and use process hollowing to load the malicious stage 2 using CreateProcessInternalA, ZwQueryInformationProcess, ReadProcessMemory, ZtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory and NtResumeThread API calls.
Finally, the PS script recursively searches for any link (.LNK) file in the above locations and modifies the “Target” parameter for all existing browser shortcuts with the flag “–load-extension=[pathOfExtension]” so that the shortcut will load the browser with the malicious extension installed.
Stack-string construction, dynamic API resolution via LdrGetProcedureAddress, API hammering, and display device enumeration defeat both static and dynamic analysis at every stage.
The shellcode then proceed to start explorer.exe and use process hollowing to load the malicious stage 2 using CreateProcessInternalA, ZwQueryInformationProcess, ReadProcessMemory, ZtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory and NtResumeThread API calls.
This buffer is then decoded, revealing the shellcode... Another buffer in then created and data is copied to it using the rep movsb instruction. This buffer is then decoded, revealing the stage 2 executable.
Since the malware later attempts to execute the payload using rundll32, it is highly likely that the final payload is a DLL...
Within the MSI, two anti-sandbox mechanisms have been identified. The first anti-sandbox measure presents a button with the label “Please verify that you are not a robot.”. In one of the samples, it was observed that a virtual environment is detected through a feature of Advanced Installer.
For example, it has the ability to retrieve the victims’ addresses, obtain account information, bypass 2FA, and much more.
For example, it can extract information through the browser, such as the system information, cookies, browser history, screenshots of opened tabs, and even receive commands from the C2 server.
For example, it has the ability to retrieve the victims’ addresses, obtain account information, bypass 2FA, and much more.
Within the MSI, two anti-sandbox mechanisms have been identified. The first anti-sandbox measure presents a button with the label “Please verify that you are not a robot.”. In one of the samples, it was observed that a virtual environment is detected through a feature of Advanced Installer.
JavaScripts: requesting commands from the C2 (left pane) and taking screenshots (right pane)
The malicious extension has various JS scripts to perform browser manipulations while the user is browsing the targeted websites, including enumeration and manipulation with cryptocurrency websites.
Stage 2 is responsible for communicating with the command and control (C2) server... the malware attempts to establish a connection to the C2 using WinHttpSendRequest.
To do so, it performs a DNS request to don-dns[.]com through Google DNS (8.8.8.8, another decrypted string) and it queries for the TXT record.
Researchers also found a malicious MSI with a Node.js backdoor that used Tor for command-and-control traffic
Downloads a shellcode, saves it as a .dat file, decrypts it using XTEA, and executes it in memory. The malware downloads an additional file from the C2 using URLDownloadToFileA...
215 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LegionLoader is referenced as infrastructure-associated malware in the delivery chain, with one Go-based variant contacting infrastructure associated with it.
An information-stealing payload delivered by OnionDrop.
A downstream payload delivered by OnionDrop. The analyzed sample used Donut-generated shellcode to unpack LegionLoader in memory; the payload dynamically resolves APIs, decrypts its RC4-protected C2 configuration, and communicates with gainmsg[.]com.
A malware family cited as previously delivered via ClickFix campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.